
Phishmas Alert: Tackling Holiday Season Cyber Threats In this episode of Cybersecurity Today, the weekend show, the host is joined by guest David Shipley to discuss the rise in phishing activities during the holiday season, humorously dubbed...
Loading summary
Jim Love
It's that time of year again when all around the world we wait anxiously for the arrival of Fishmas, that magical time when there's no nice, there's only naughty. As the Fishmas elves go from website to website, stealing the gifts of passwords, credit card numbers and personal data.
David Shipley
Huh? What?
Jim Love
What? What was that? Oh, so. Man, so dozed off there for a second. Boy. What day is it? What? What day is it, boy? It's Fishmas. Clever boy. Oh, David, you're here. Welcome to Cybersecurity Today, the weekend show. My guest today is David Shipley and this is what we've called the Research show. Both David and I are passionate about good research. We like research that's factual when you can or where you can take away something useful. And that's where the examination and discovery comes into the pictures, people. Even the best research can give you just data. Notice I didn't say facts. People often confuse data with facts. What's the difference? Facts involve more than simply looking at data you've collected. Data can be an opinion, data can be skewed, data can be part of the puzzle, it can be accurate and still proved to be wrong, like the polls in an election or oh no, we won't go there. We're not going into the land of politics. So for data to make its way into the world of facts, you have to be able to extrapolate the impact of the data and ask yourself, what does the data mean? And that's where we can get into some neat things like just because one thing happens at the same time as another doesn't mean they cause each other. We've all been through that. My famous example of there's a strong correlation between ice cream sales and drownings, but that doesn't mean that ice cream consumption causes drownings, but both happen in the summertime. Which is my long witted way of saying that oftentimes you have to dive deeper into the data, discuss it and find out what you can take away that you can actually use. And in the spirit of Fishmas, which is like Christmas, only it happens earlier, here's another correlation. The closer we get to Christmas, the more fishing that happens. And David, I'm going to open up with that. What is it about this season that makes everybody go nuts on fishing?
David Shipley
First of all, I think a lot of criminal gangs operate on the calendar fiscal year, so it's Q4 for everybody right now. And, and they're working those numbers right, so it's a busy time. But obviously of course the amount of pressure individuals are under at work is very high this time of year. The interpersonal pressure can be very high. This creates tremendous opportunity and of course, the volume of communications and the incentives that the retail sector is putting out. There's a reason why Black Friday is Black Friday. For those not familiar, that is the point in time traditionally when retailers actually make their money. Between this mid to late November and December 31, right before the Boxing Day kickoff. This is the super bowl of retail. And in that environment is the perfect conditions for fraud, for success. You've got the human minds are prime, you've got the serendipity effect. This is something I think we need to research more about how much more probable it is someone's going to click on an Amazon fish when there's so much thinking and doing about Amazon in that particular moment.
Jim Love
Yeah. And I bring this up and it's so funny because I started out in retail a long time ago selling jeans at Thrifty's Just Pants in Toronto on the corner of Church and Queen. And the thing that you pointed out was absolutely correct. I couldn't believe it. But this was. You made all of your money in that Christmas season, if you were a retailer. And then the after Christmas, the sales and the margins went way, way down. And I was really amazed when we pile up all this stuff and put it into a sale at the exhibition ground for anything that didn't go, they sold it for peanuts. Yeah. So there's the sheer volume of activity and as you said, it's Q4 for these cyber criminals or whatever you want to call them. And so there, there is a big increase. And we looked at this report, speaking of our research, we've got this report that I'd gotten, which was a 2024 online holiday retail threat report, came from a firm called B4AI, which before AI, researchers analyzed 6,000 retail domains and they found over 4,000 of them used retail keywords, brand names like Walmart, Ikea, Amazon, Flipkart. And then they'd manipulate these, adding words like shop, deal, and a thing called typo squatting. Do you know what that is, David?
David Shipley
Yeah. So this is where you're looking for domains that are one letter or one number off of the legitimate domain. And really what they're taking advantage there is our human brain. Sometimes, particularly when we're tired, we'll see what we want to see. So if we're tired and we're quickly looking at something. Yeah, that's the Amazon website and it might be amazons.com not Amazon.com. and obviously there's this cat and mouse game that goes on back and forth between legitimate brands and there's a whole subsector of security firms that actually just go looking for typo squatting, domain squatting kind of names and try and get them taken down, buddy. Because now you're going to get a.
Jim Love
Lump of coal if you use that language on the show.
David Shipley
So now you've got Amazon Shop, you've got Amazon Ticket, you've got Amazon Deal, you've got all of these ridiculous domains. Not to mention the fact that you've got a world's worth of country domains sometimes can be really helpful. Again, you can see where I'm going with this. You can create an infinite number and you can do some of the things they noted like eBay Dash 088. And keep in mind the whole goal here is just have something with the name in it that's going to be able to be recognized and use that brand. And what's interesting from the study is that their notable use of.comshop, vIP and XYZ like Dear Global top level domain registrars, why did we need xyz? Like we were not running out of domain names and we're like, that's it, can't find it. I'm just gonna have a dot XYZ like amazing, thank you for that.
Jim Love
And some of these have been around a long time and that's what I find that a little amazing. They gave a couple examples at Walmart gift card 0 and dot whatever and GoDaddy sites. You know com or whatever. And these date back to 2013. Some of these are, are old.
David Shipley
Keep in mind that some of the ways that emails get evaluated, sending domains, links, et cetera, some of the clever things that we do with machine learning models on the defensive side, go and look at the age and history and relative reputation of sites. So like a fine aged wine, fine age domain. Because like many email systems, many endpoint detect are going to be like, hey, this new Walmart one two three was registered in October 2024. That seems sketch, right? This is a cow. So that's where it gets to what. What I find funny is we don't know how many of these domains that were registered were by criminals or by people like David who run security awareness companies. And we've got 200 fake domains, right? And so that's not answered in this research report. Like there's no global registry of is this domain a scam or is it a simulated scam?
Jim Love
So training scam?
David Shipley
Yeah, training Scam.
Jim Love
Yeah. Yeah. Okay. So that might explain why some of them around and I would guess that they would trade hands and stuff too. A domain could be around and could be sold. It could just temporarily lapse and be picked up again. There's all kinds of things that can.
David Shipley
Happen to these and actually you're onto something really interesting for small and mid sized business folks listening to this call, you might have created a subdomain or a promotional domain or another domain and you just, okay, we're done paying that $20 a year renewal cost and away it goes. Like recycled domains have incredible value on the side. So that's interesting to think about the digital environmental cost of domain name proliferation and domain name reuse and abuse, given the aforementioned point about reputational history.
Jim Love
Yeah, and we haven't even gotten into the substitution of characters for domain names and some of the sophisticated stuff where you can actually use a different character that's from another language or another keyboard set and, and it looks like a one and you can do all of those things. The fact is this stuff looks pretty convincing. So a lot of the stuff that we train people to do, which is to check out the URL, is that now useless? I wouldn't say, oh, I've asked the tough question.
David Shipley
I wouldn't say it's completely useless if only it's ways of people stopping and processing and thinking. But the challenge is we've made it so friggin difficult to see URLs safely, particularly in mobile context and other things. It can just be really hard to properly check this. Which is why like giving employees an opportunity to use tools that can do this work for them, reporting the fish and getting an analysis feedback back on it could be helpful. I think we put too much on the end user to puzzle out some things when we could be helping teach more meaningful signals like hey, does this deal seem too good to be true? Do you normally get your Walmart emails at work? It's hard. But the other part is, and this is where some of our research work is leading us, is fatigue and the impact on the human brain and cognitive load. What we can easily observe when we are not stressed, not tired and not information overload is different than when all those other factors are in play. The old advice of just look for the grammar, the typos and the crappy links, it was all done from a perspective that this was about intelligence. So someone being smart versus dumb versus someone being human and not human, I'm not going to completely dismiss it. It's just that we've seen greater success teaching people about the emotional indicators than we have just purely the technical indicators.
Jim Love
And a lot of these names imply trust. People shop at Walmart, they use Amazon. These are. And I don't know about everybody else here, my wife doesn't listen to the program, thank God. I'm sometimes a little behind in my Christmas shopping and if I saw something pop up that looked pretty good, I might go, oh, and I don't know, I think anybody could get fooled. So we've got the stress of the season, we've got the familiarity of it, and those things can more or less beat you on this. I guess you've given us one clue, and that is people need to think critically about the entire message.
David Shipley
Yeah. This is why you should keep your personal life in personal email and not in your work email. Don't use your work email to do your online shopping. And I know all of a sudden the next objection someone's mind is, but David, I don't want my spouse to see what I'm ordering. Cool. Create a burner email address for your online shopping so that you have that separate. But that way you're lowering the risk inside your work environment. They specify a lot of this. The work side is that while criminals obviously want to target and perpetrate frauds and particularly steal information, no doubt in my mind that a good holiday fish has brought down many an organization because of all the reasons that make it work.
Jim Love
These sites are no longer the sort of the poor knockoff of a site. They look exactly like a real Walmart or Amazon or Google or GoDaddy's page. I've seen a couple of them. They would fool you with the look unless you really knew what you're looking for.
David Shipley
The research report, you know, showed some good examples once, but also some really poor ones. And I'll be honest, the poor ones can still work because. And again, this is where it comes back to the intelligence side. If someone's in a rush and the deal is too good to be true. And I can just picture Jingle all the Way with Arnold Schwarzenegger and they're running for that toy because as negligent husbands, they didn't do what their wives told them, which was order it well in advance. And then they were running around the entire city in a very stressful way. But when you're now frantic and running through your brain can work against you so they don't actually have to be that good. Now what's terrifying is again, to your point, with AI, they are getting better and Scalable and it's easier to clone and it's getting that Catamouse game. What was interesting from the report that I thought was interesting was the amount of these sites that are trying to get people to download and install apps that. That stood out to me.
Jim Love
Yeah. I think the app thing is. I don't think it's new, but it adds a new dimension to this and that is these fake apps from apparently legitimate retailers. And that's a killer because most apps have a login and you get comfortable with them. How did they. I don't know how they get them into the stores, but they do.
David Shipley
And yeah. And it comes down to too. Now remember, this is also where the EU has not necessarily been our friends when it comes to cybersecurity and the whole issue of forcing the ability to use non Apple app stores in certain jurisdictions. And Android's had this for a while. You could sideload apps, you can use non Google app stores and be careful where you shop and where you buy and where you install your stuff from. And some of these apps are just downright nasty in terms of their ability to go looking for credentials. Keystroke capture that type of shenanigans because it's trying to steal your money. So that was interesting on that side of the report.
Jim Love
Yeah. The gift card thing was. Is another one that happens at this time of year in the ex.
David Shipley
Yeah. In the example in. Here's what's interesting. Right. Just looking at the research report and I thought this was fascinating. Following the steps to claim your 750 Walmart gift card and they walk you through. Just click the get started button. This is familiar language. Enter your email and basic info, complete the product poll, complete several recommended deals and claim your rewards. So what's interesting here is it's just believable enough. Okay, I'm gonna get a $750 real gift card. This is amazing. Oh, I just gotta buy some stuff to get that. Oh, this is even better. And I'll get the deals and I'll claim my reward. It's great construction. But here's the beautiful thing about these criminals is that they learn. Right. I've said this before in the podcast, is that criminals are lazy, but they're not stupid. If they were, if they were just harder working, they would be legitimate business people. The fact that they, that this works means that they're going to continue to leverage it.
Jim Love
Yeah. And so these things, this is you decide you're going to. You're going to actually get a free gift card from them but you've given them all this information. So just a fake out to, to get you to give more information and you're supposedly going to wait for your $750 Walmart gift card.
David Shipley
Yeah. By completing the recommended deals, my guess is they're capturing all the critical credit card information. Expiry date CBV 2 and away we go. And I would not be surprised if there weren't live operators behind some of these things, literally capturing these as they go and, and placing orders. And who knows, maybe they've actually sent some people a 750 gift card after they've stolen several thousand dollars from them.
Jim Love
Yeah, maybe I just looked at it wrong. I wouldn't believe the $750 but if you actually put $50 on that or 75 bucks on that, I might believe it.
David Shipley
And again, AB testing is a hell of a drug. My guess is that there's lots of different models out there trying this out. And yeah, there was a theory, a hypothesis that came across once before and it's interesting to see this in the data set that sometimes the criminals choose their lures because they work on a very specific group of people and that that's an interesting hypothesis that in some ways they want to weed out the Jim Loves. A Jim Love might be the type person who looks at this or they.
Jim Love
Don'T have to pay him as much because he's that, because he's not stupid but he's cheap.
David Shipley
So it's interesting, right? And this is where we flag the risk of AI is that the ability to create and conduct AB testing at hyperscale, at hyper speed is what keeps me awake at night about the future of fishing. So imagine you can have a system that dynamically creates these websites, is evaluating the results, has this giant big data feed of the Dave Shipley's the Jim Loves everybody else, starts figuring out what patterns are between these and just makes those subtle tunes. And one thing I can tell you about this, subtle changes in language, just small tweaks. Maybe it is your point. The $50 versus the 750 they can dramatically increase success rates. And this is in Some respects Marketing 101 Nudge Theory for those that follow that. But this is where I start to think about this. And the sheer scale and size of these activities overwhelms any chance at an effective policing response. And I would add this, we talk about the inflation crisis that continues to be a challenge for western governments and retailers are just getting hammered left and center and they're pouring money, bucket loads of money. Into fighting these surges and that's just further eating into retailers and that's bad news for all of us.
Jim Love
Yeah, and we've talked about this before a lot is how you keep the sense of urgency and emotionality into to, to get people to get to that point where they're easier to fish. And if you're Canadian sale. Eh, I'm sure if you're American too. But these things are often not just gift cards. They're, they're loaded with things like the biggest sale of the year, billion dollar sale, all of those things to keep the pressure on you. And I presume they, they do the same thing of trying to make it limited time offer and all those sorts of things.
David Shipley
Yeah, Marketing works for retailers and for criminals. Marketing is the arms dealer of the human mind. Right. Ethical marketing uses effective messaging to create values between individuals and organizations. And like I used to be a marketer, probably still am in the broadest sense of the word, even when I'm a fisher of men as they are. But at the same time really this is all about intent. And so the cool opportunity, presenting ourselves in understanding how to combat phishing and social engineering is that none of this is about computer science. All of this is about psychology, marketing, neuroscience, criminology. And that's where we need to invest more time in.
Jim Love
Yeah. And they get better and better at pursuing it. You talked about this having customer support available for these places that makes you feel like, oh they've got customer support, they have to be real. And now I guess with AI it makes it even easier to have cheap customer support.
David Shipley
Absolutely. And what was interesting in this report was noticing the use of chatbots to add some additional authenticity. Now what I thought was interesting about this is I got thinking about how these chat bots, particularly if they're powered by AI, could be used to help push the deal. So they land on this phishing link. It's a website, it's got the Walmart offer. That's too good to be true. David pops up. Hey, can I help answer any questions? Is this a scam? Of course not David. This is a great offer. Limited time for people just like you. And I'm happy to answer your questions. How does it work? You complete some orders and because of that you're going to get this gift card. So you know, you can go ahead and buy 750 and you're going to get it all back. Really? Walmart's doing that? Yeah, we want to increase our brand awareness. You can literally see how an evil LLM could Be tuned to then further reinforce that.
Jim Love
Yeah, yeah, yeah. And these are. We've focused. These are mostly focused on the consumer. You pulled up a report that talked about some of the things that were affecting the retailers. I think you had another report that you were looking at.
David Shipley
Yeah, this was a. The retail and hospitality ISACs 2024 holiday season sort of trends. And this looks at it from the retailer perspective. And obviously what was interesting from 24 is that while direct sort of attacks on accounts and credentials, that was a thing. Ransomware targeting the actual retailers was particularly intense in this period and in particular forms of malware were very prominent. So it was very interesting to see that in terms of the attacks. And what I thought was interesting is the top reported threat actors last year by a long shot was our loosely affiliated group of typically younger teenage males known as Scattered Spider, or by others as the Comm or the Community. By the way, don't go goulding or joining that telegram group. That's not a fun place on the Internet to go. But they were ahead of more traditional organized crime groups like Fin6, Fin7, Carbanac and others by a long shot. So that was interesting to see. And what I'll say broadly is it's part of this massive fraud issue that we're seeing. I just spent Monday in Ottawa meeting with various agencies, intelligence agencies and others. Fraud is through the roof in Canada and the United States. In the states, there is $10 being lost for every dollar in ransomware being made to fraud. So there's 10 billion in fraud. There was a billion in ransomware payments. We tend to get all excited in the cybersecurity industry about ransomware, but it's fraud that is winning by a long shot.
Jim Love
What kind of fraud? Obviously the one I've been seeing a lot has been the false invoice fraud, which I think it's just gone crazy. I've never gotten so many invoices and I've never known whether the it was because the attachment had some ransomware attached to it or if it really was an attempt to fool me into paying something.
David Shipley
So what we've seen from the data is. So that kind of invoicing, false email, business, email compromise kind of theme. So false payments, wire transfers, invoicing, et cetera, that's about 2.9 billion. The 10 billion I just referenced is pure consumer fraud in the US it's out of control. Again, when we're talking about that, we're talking check fraud, we're talking count takeover, we're talking romance scams, we're talking crypto, but it is bigger business by a long shot than pure professional cybercrime targeting organizations. And I have theories as to why that is.
Jim Love
Which you're going to share, right?
David Shipley
Why police are overwhelmed. And so they are triaging big ticket attacks. If you do a multimillion dollar ransomware attack against a prominent US target, you're giving a lot of heat. You're getting the whole of government to wog. You hit grandma grandpa up for less than 50,000 or in many cases under 5,000. Nobody's knocking on that door right now. And in Canada, Jim, one of the things I just learned, and this information is very troubling, that there were 400,000 calls to the Canadian Anti Fraud center last year. Do you know how many of those calls they were able to answer?
Jim Love
Oh, don't tell me I'm a hundred thousand.
David Shipley
Thirty thousand. We can answer seven.
Jim Love
I thought I was really lowballing it.
David Shipley
Thirty thousand we can answer 7.5% of the fraud calls going in there. And these fraud calls aren't just the ones the good Samaritans are saying, ha, I spotted this fraud. They didn't get me. But I wanted to alert you, that's part of it. Many of these calls, Jim, are people that lost significant amounts of money. Some of them they're life saving, some of them may be suicidal. And this is one of the most important victim impact services to cyber fraud we could be having. And operators are not standing by. They don't even have enough. And I found out this week that the team there, the budget was cut last year. Paradoxically, as things continue to work, the budget was cut and it's anticipated to be cut again because of shifting funds to the new headlines that are gathering, garnering political attention and public interest. So at a time when fraud is even worse, when policing is already overwhelmed, we're going to cut it again. Which is just stunning. Just to add into the context, these research reports are screaming an alarm to us both. What we're hearing from this report from the cybersecurity company, the volume's up, the activities up, scams are getting better, they're getting better at delivering different things. The ISAC reports are saying, hey, more people are getting involved in this and the numbers are up in terms of the cost and the policing is going down.
Jim Love
Oh yes, the leadership of our government and I'm, I, when I say this, I'm not being political. I think they're all, they all make me crazy, whatever party they, they are. But we, how can we do that? To our most vulnerable citizens. I just, I, I don't see a lot of education, I don't see a lot of intervention, I don't see a lot of prevention and God forbid I don't see any use of AI. Cybercriminals are using AI effectively. The government could be using it very effectively too. They could phone every person over the age of 65. They could. There's so much they could do. I'm not the expert at this but it seems like they're doing nothing.
David Shipley
Bare minimum. Bare minimum and budget cutting to bare minimum. And that's not a slight to the hard working people across the country trying to make a difference in this fight. But it is huge and to go back to where we started, criminals who go where the cops are not crime 101 and the cops aren't online and they're not looking out for you for small amounts of fraud. So what do we do about all of this mess? What is the total sum? Is it just abandon all yeho, turn your computers off, throw it away and get off the Internet. Shop local is also not the worst idea. I will put my Fredericton Chamber of Commerce hat on just for tiny minute.
Jim Love
I totally for personal and I will tell you if you really want to keep keep your money safe, go to downtown Halliburton and downtown Minden or wherever you are and buy something from a local merchant. You'll do doubly good things.
David Shipley
So that's a strategy I think being kind to ourselves as human like the kind of security awareness that we need to start focusing on more than just the technical indicators of a fish. It's like hey, when you're gonna go do your online shopping, make sure you're rested, you had a good meal, you're distraction free. Set some time aside to go do it. Go directly to the websites themselves. You might see a deal in an email. They'll usually have a code in the email. Just take a look at that and go and look and see those deals directly on the websites themselves. Listen to your gut. If it seems too good to be true, Walmart is not going to give you a $750 gift card for buying a few items in the store. Think about these things. Take a break, talk to somebody else. Hey, this is an interesting deal. Maybe I should just ask somebody about this. Hey, what do you think of this deal? And in the process of that conversation you'll give your brand a chance to get out of emotional arousal and into conversation and you might just save yourself some money. Slow down. No we're busy. I know this season is intense. Slow down.
Jim Love
Yeah. Which is good advice. But I can't see most of the population who is vulnerable following that advice. And I maybe there is nothing a government can do, maybe there's nothing others can do, but I think we have to find a better way to tackle this. Not taking anything away from your advice. It's as and it does work if you do it in a household. And I said my wife doesn't listen to the program, thank God. But because she always hates me talking about her. But she's the best person to actually say, and I admit it, she's caught a couple of things that I might have missed coming in because all of this time I've been talking to her saying, take your time, relax, take a look at it and think. And she'll come back to me with things that she'll spot that I wouldn't. So that works. I don't want to take anything away from that. People could do that with their family, with their children. We don't teach Home EC anymore. We don't teach budgeting or anything useful in schools most of the time. But we could be teaching our family to be responsible. And I think that's probably a good place to start.
David Shipley
And I think the biggest thing and I, it's funny, I was, I, I've just got back of two and a half weeks of nonstop travel in the US I've been from Miami to DC to Atlanta, back to Ottawa and finally.
Jim Love
Home and stalking you on LinkedIn.
David Shipley
So, yeah, been a lot of places. And one of the conversations I've had with a few people is leading again, leading with that empathy. And so it's in the cases of it was executive and her parents had fallen victim to a scam and she was so frustrated. But it was like, remember, it's not about how smart or dumb people are, it's how human they were in that moment. And she said as she was dealing with what happened to her mother, she was empathetic and she listened and she gave some advice about how to avoid this happening again. And it was more well received and so less shaming, more listening, understanding and setting people up for success. But on the theme of setting up for success, what are some of the other things we can do? Obviously, keeping your devices up to date. If you're doing online shopping, make sure that your machine is patched, has antivirus, has good hygiene. This is the equivalent of winter driving in Canada before you're going to want a road trip. Winter driving, you should make sure there's this thing called winter tires for those listening in the southern states. You may not be as familiar with those, but they are adapted for our winters. You make sure you got windshield washer fluid, a warm blanket, if you break down, you got enough fuel, et cetera. These are the same things that are required for the information superhighway. Good thorough planning and preparation make for safer travels and happier times. And just don't think that all this automagic stuff is going to protect you on its own without you being an active participant. And I would think the, the other part of this, that that matters a lot. I think how we educate people in context, we don't study this issue nearly as much. Angela Sasse is a prominent researcher in the, in the European Union. She's done a lot of work about how we could be better informing systems to give interventions or educate users in context. And is there a role for online retailers and providers to potentially provide education to their customers in your personal profile, in other things.
Jim Love
You know, I was thinking about that and there are things, I'm always surprised when I hear people say things and I wish they would do more of it. Like the government of Canada will never ask for this information. They have all kinds of online contact with people adding a little of that. Maybe that. Shouldn't that be a retailer's responsibility like a Walmart to say a lot of people impersonate Walmart. If you need to figure out how, whether where they're impersonating us or not, call 1-800-WALMART and again, these could be automated, but I just, I don't see enough outreach happening from retailers themselves.
David Shipley
And part of this is again, the margins for retailers are not been massive. These are not big tech companies. And so this is, I understand the profound thing that I'm saying and just wondering, this is an opportunity for innovation, I believe, and in fact transparently. We're actually doing some cool work with banks on consumer fraud education in their mobile banking app. And because for those bankers or others in the financial industry listening to this, the populist tide is turning against banks in particular with respect to people losing money. And you know, the UK has made moves to hold banks accountable. There was a paper published by the Canadian Federal government, the consultation period just ended, which was asking questions like perhaps banks should be on the hook for a certain level of fraud up to a point, which is a super bad idea because if people don't feel like they're going to be accountable and responsible for behaving safely, they won't and that could increase fraud by 30 or 40%. If the research we've done on people not feeling like they play a role in protecting their employer and falling victim to phishing, if I make that sort of hypothesis, if the rates are the same, we could be letter literally setting the fraud losses from 10 billion to 14 by saying the bank's going to pay for it, we're not going to see it, it's just going to get socialized across to everyone else. So I think shared responsibility model where there's a push to get people educated could help.
Jim Love
Yeah, and there is some. We did a, a report on a study that really said that one of the reasons people would move is if they had heard something about their bank, about fraud that made them distrust their bank. Now I, a hundred years ago when I was in financial services, back when we were, you know, chipping the all of our records into stone, they were looking at people never changing their bank. You'd start banking, you'd stay at that bank forever. And we always found that there were these points where people would move marriages, significant birthday or significant birth in the family, significant pivot points. And hearing about a major fraud or being experiencing a major fraud may be one of those new points where people would, might switch. And that was what the research was saying.
David Shipley
No, I think, I think that's part of it. I think some of those things being proposed in Canada to combat fraud at the financial services level, maybe online retailing needs to have a component of that as well. What are the best practices that need to be regulated? But again, I an hour in Ottawa trying to advance Bill C26, which has been in progress for six years, trying to keep the literally and figuratively in this country. So my hope that they will move on to targeting fraud, given the fact that hospitals are a burning nightmare, pretty low. I'm pretty jaded right at the moment. But I'm, I don't know, not completely out of the fight.
Jim Love
No. I'm of two minds in this. There are people, Senator Colin Deacon, if you Follow him on LinkedIn this, he's a breath of fresh air. And he was pointing out some private member bills that people were raising to be able to do things, to get things moving forward. And I went, why do. First of all, who are these private members? Could we have their names so we can go vote for them? The second is why does it take a private member to get legislation that makes sense? And that, that drives me crazy. This bill C26 or like I'm just, I'm Apoplectic about how many years that is. I just can't. I can't even. I start, I start to shake when I think about that. It's like listening to somebody. And I'm not dumping, not on the people who are working. The people who work for the government are hard working.
David Shipley
Yeah.
Jim Love
But we've lost our direction both in the US And Canada, I think in terms of leadership. And it really makes a big difference when people will tell me that they're going to. They're studying something and they've been at it for, you know, three months. Looking at this thing, I'm saying, you are no longer part of the world as I know it. It's moving far faster than that.
David Shipley
And I think the political parties that figure out how to address the growing online fraud problem, that, that extend well beyond fishmas, that continue all year round, I think are the ones that are going to gain attention, particularly in the political culture and climate. We're in today with the Go to get turning this into a political podcast. But you asked what can we do about this? And we talked about the vigilance that people could do. We talked about the technical steps people could do. And none of these are silver bullets. But also none of these are going to be worth a damn if the neighborhood keeps getting worse and worse and worse online. And so the best thing that listeners can do to this, what do we do to change the game is actually demand that politicians actually care about this and talk about it and look at common sense initiatives to actually combat this, including, I don't know, funding the online crime portion of your national police forces to deal with where all the criminals ran off to and everyone's patting themselves on the back that physical crime and various things are on the downward slope.
Jim Love
This is amazing.
David Shipley
Yes. Because cops are in the real world. They're not in the virtual world. So let's give Santa Claus a win. Let's protect Santa the rain deal from fish miss and let's start, start actually tackling this problem.
Jim Love
Wow. I think we're going to leave it there, David, that's we've solved world hunger and this problem. But I think the issue is that hopefully we as professionals will take one piece of advice from you and that is no shaming, have those discussions. But the second is we, and we said we're not political and we're not. I'm not anymore. I've got no time for. From all of them. But I know that they will do what people are excited about and what people talk to them about. So Send your MPP or your MP a phishing email. No, not a phishing email, a regular email. Sorry, that just slipped out. Send them an email or God forbid, when the strike's over, send them a real letter and tell them that you really do feel the fact that your grandmother or your grandfather or your elderly relative or somebody in your family could be defrauded and they're not putting enough muscle behind it. And I think those, if we feel that way and we express ourselves, maybe they'll, we'll move the, the play just a couple more yards down the field.
David Shipley
If we can save one more senior from heartbreak, if we can rescue one Christmas from holiday fraud, is that not worth quick email, a quick action to legislators, everyone. I know we're trying to wrap up, but we all talked the big game about the holiday spirit. And maybe the holiday spirit also involves looking out for each other and thinking about a better next year and a better future. Because I would love to say that at the end of this podcast, this time next year, we'll say Fishmas was canceled. Not going to be next year, but I would love to say a day where. Do you remember when there was a thing called Fishmas? And we've now turned the page on that. Wouldn't that be nice?
Jim Love
Yep. It's only once a year, Mr. Scrooge. David, thank you. Thank you to our audience for listening to this. Hopefully we didn't get too morose about it, but we did want to really put out some of the research out there, talk about some of the things that were there, give you some insight to them. And if we hit the mark, let me know. If we didn't hit the mark, let me know. Editorialchnewsday ca. You can reach me there. Thanks a lot. Thanks to my guest, David Shipley. Merry Christmas, David. We'll probably have one more show before then, though.
David Shipley
Absolutely. I guess. Happy Black Friday Cyber Monday. To those that celebrate, I hope for a Merry Christmas, not a Merry Christmas.
Jim Love
And that's our show. We have links to the two reports. They'll be in the show notes. You can find those@tech newsday.com or C. Take your pick. And once again, thanks for listening.
Cybersecurity Today: Phishmas Alert – Tackling Holiday Season Cyber Threats
Episode Released: November 23, 2024
Hosts: Jim Love and Guest David Shipley
As the holiday season approaches, cyber threats intensify, presenting significant risks to businesses and individuals alike. In the episode titled "Phishmas Alert: Tackling Holiday Season Cyber Threats", host Jim Love engages in an in-depth discussion with cybersecurity expert David Shipley to explore the nuances of this heightened threat landscape. This summary captures the episode's key discussions, insights, and conclusions, enriched with notable quotes and timestamps for reference.
Jim Love introduces the concept of Fishmas, a play on the word "Christmas," symbolizing a period when cybercriminals ramp up their phishing activities. He humorously sets the tone by describing Fishmas as a time when "Fishmas elves go from website to website, stealing the gifts of passwords, credit card numbers, and personal data" (00:02).
David Shipley provides insights into why the holiday season is particularly lucrative for cybercriminals:
Jim Love relates this to his retail experience, highlighting how sales peak during Christmas and plummet afterward (03:32). This cyclical nature mirrors the increase in cyber threats during the same period.
The discussion delves into typo squatting, a technique where cybercriminals register domains that are slight variations of legitimate websites to deceive users. Jim Love references a 2024 online holiday retail threat report by B4AI, which analyzed 6,000 retail domains and found over 4,000 employed retail keywords combined with tactics like typo squatting (04:51).
David Shipley explains:
"Sometimes, particularly when we're tired, we'll see what we want to see. So if we're tired and we're quickly looking at something, yeah, that's the Amazon website, but it might be amazons.com, not Amazon.com." (05:36)
He emphasizes the sophistication of these domains, noting the use of various top-level domains (TLDs) like .shop, .vip, and .xyz to mimic legitimate brands (06:38).
Jim Love and David Shipley discuss the evolving role of Artificial Intelligence (AI) in phishing:
David Shipley warns:
"The risk of AI is that the ability to create and conduct AB testing at hyperscale, at hyper speed, is what keeps me awake at night about the future of phishing." (16:57)
A significant portion of the episode contrasts fraud with ransomware, revealing that fraud poses a more substantial threat:
David Shipley states:
"Fraud is through the roof in Canada and the United States... fraud is bigger business by a long shot than pure professional cybercrime targeting organizations." (23:58)
The episode highlights the inadequacies in current policing and governmental efforts to combat cyber fraud:
Jim Love expresses frustration with the slow governmental response:
"But we have to find a better way to tackle this... I don't see a lot of education, I don't see a lot of intervention, I don't see a lot of prevention." (26:17)
To mitigate the risks associated with holiday cyber threats, Jim and David offer actionable recommendations:
David Shipley suggests:
"None of this is about computer science. All of this is about psychology, marketing, neuroscience, criminology. And that's where we need to invest more time in." (18:18)
Both hosts emphasize that combating cyber fraud requires a collective effort:
David Shipley advocates for:
"A shared responsibility model where there's a push to get people educated could help." (34:45)
In wrapping up the episode, Jim and David rally listeners to take proactive steps:
Jim Love urges:
"Send your MPP or your MP a phishing email. No, not a phishing email, a regular email... tell them that you really do feel that your loved ones could be defrauded and they're not putting enough muscle behind it." (38:32)
David Shipley envisions a future where:
"Maybe the holiday spirit also involves looking out for each other and thinking about a better next year and a better future." (40:43)
Key Takeaways:
For more detailed insights, listeners are encouraged to access the reports mentioned in the episode via technewsday.ca.
Note: This summary is based on the podcast transcript provided and aims to encapsulate the critical elements discussed by Jim Love and David Shipley regarding holiday cybersecurity threats.